CVE-2019-25052
In Linaro OP-TEE before 3.7.0, by using inconsistent or malformed data, it is possible to call update and final cryptographic functions directly, causing a crash that could leak sensitive information.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/OP-TEE/opteeos/commit/34a08bec755670ea0490cb53bbc68058cafc69b6, https://github.com/OP-TEE/opteeos/security/advisories/GHSA-pgwr-qmgh-vhmf, https://github.com/OP-TEE/opteeos/commit/34a08bec755670ea0490cb53bbc68058cafc69b6, https://github.com/OP-TEE/opteeos/security/advisories/GHSA-pgwr-qmgh-vhmf
